# Resolve someone else’s access request

> Source: https://elaichi.ai/docs/api-reference/access-requests/access-request/resolveaccessrequest/

`POST /access-request/{id}/resolve`

Resource: **Access Request** · API: **Access requests**

## Path parameters

- **`id`** _(string, required)_
  Access request id (`areq_…`).

## Request body

- **`decision`** _(string)_
  Allowed: `approved`, `denied`
- **`note`** _(string)_
- **`resolution`** _(string)_
  Only meaningful on an APPROVED, `reason: "restriction"` request. `grant` (default) writes an access grant; `policy` approves without writing one — the admin is changing the underlying rule directly instead.
  Allowed: `grant`, `policy`
- **`expires_at`** _(string,null)_
  When the grant this approval writes auto-expires. `null`/omitted means no expiry. Ignored unless this approval actually writes a grant.
- **`remove_member_rules`** _(array<string>)_
  The ids of the personal rules of the requester that this approval would edit, as the caller confirms them: must equal the conflicting set EXACTLY (an empty array asserts there are none), or the call answers `409 member_rule_conflict` with the real ids in `error.details`. Omit the field to skip the check (legacy behaviour: the rules are edited without confirmation).

## Response body

- **`id`** _(string)_
  Access request id (`areq_…`).
- **`requester_user_id`** _(string)_
  User id (`usr_…`) of whoever filed the request.
- **`tool`** _(string)_
  What was asked for: a tool name, or a connector slug when `resource_type` is `"connector"`.
- **`resource_type`** _(string)_
  Allowed: `tool`, `connector`
- **`connector_slug`** _(string,null)_
  On a `"tool"` request, the connector the tool lives on when the request named one — what makes approving it able to lift the restriction on that tool. Always null on a `"connector"` request.
- **`connector_label`** _(string)_
  Display name of `connector_slug` (or, on a `"connector"` request, of `tool` itself) — resolved from the catalog in the same batch as `tool_label`, falling back to the slug. Present on every view: the requester reads it in the self view exactly as an admin does in the queue, so it lives here rather than only on the admin shape.
- **`connector_logo`** _(string,null)_
  The connector’s mark for the same slug `connector_label` names — the icon-first, logo-second image the Connectors page and every other connector picture in the console already use. `null` when the catalog has no mark for the slug; present under the same conditions as `connector_label`.
- **`reason`** _(string)_
  What kind of refusal this request is asking to be reconsidered.
  Allowed: `permission`, `restriction`
- **`permission`** _(string,null)_
  Present only when `reason` is `"permission"` — never populated for a `"restriction"`-reason request, on either write or read. That is the disclosure rule: a restriction refusal never names the rule that blocked the caller, so this field must not become a second channel for the same fact.
- **`note`** _(string,null)_
  Optional free text from the requester, ≤ 2000 characters.
- **`status`** _(string)_
  Allowed: `pending`, `approved`, `denied`, `withdrawn`
- **`created_at`** _(string)_
- **`resolved_at`** _(string,null)_
- **`resolved_by_user_id`** _(string,null)_
  User id (`usr_…`) of the admin who resolved it.
- **`resolution_note`** _(string,null)_
- **`updated_at`** _(string)_
- **`requester`** _(object)_
  Resolved member profile. Falls back to `{ id }` alone when the profile row no longer resolves.
  - **`id`** _(string)_
    User id (`usr_…`).
  - **`name`** _(string,null)_
  - **`email`** _(string)_
  - **`avatar_url`** _(string,null)_
    The person's picture — the same one the console's user menu draws: their stored profile picture, else a Gravatar URL (`d=404`, 96px) derived server-side from their email (the address itself is not sent), else null. Draw initials when it is null or the image fails to load.
- **`resolved_by`** _(object,null)_
  Resolved member profile. Falls back to `{ id }` alone when the profile row no longer resolves.
- **`can_resolve`** _(boolean)_
  True while `status` is still `pending` **and** the row is not the caller’s own — the two preconditions `resolve` itself enforces (`409` and `403` respectively).
- **`can_withdraw`** _(boolean)_
  True when the caller is the requester and `status` is still `pending`. Present on this shape as well as on the self view: an admin’s own request sits in their own queue, and withdrawing it is the one verb on that row that is theirs.
- **`will_lift_restriction`** _(boolean)_
  On a pending restriction-reason request approving could act on (a connector request, or a tool request naming its `connector_slug`): whether approving it would actually lift anything. Absent on every other row.
- **`connector_restricted_for_requester`** _(boolean)_
  On the same rows, for a TOOL request only: true when approving lifts nothing because the requester’s WHOLE connector is restricted — one tool cannot be carved out of a connector restricted whole, and an approval never opens the whole connector for a one-tool ask. Their connector access is what an admin would have to grant instead.
- **`inherited_from_member_rule`** _(boolean)_
  On the same rows, for a CONNECTOR request only: true when approving lifts nothing because the connector is a fork and a restriction written for the requester personally blocks the connector it was forked from. A fork inherits its original’s block (forking must not evade one) and an approval never overrides a rule written about one person, so the fix is to approve their access to the original or edit their restrictions. A block inherited through the requester’s ROLE is not this: approving the fork lifts it (`will_lift_restriction: true`).
- **`inherited_from_connector_label`** _(string,null)_
  With `inherited_from_member_rule: true`: the display name of the connector it was forked from, or `null` when it cannot be named to this caller (private to someone else, deleted, or the catalog did not answer). Never a slug or id.

## Code examples

### curl

```bash
curl -X POST 'https://api.elaichi.ai/access-request/<id>/resolve' \
  -H 'Authorization: Bearer $ELAICHI_API_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{"decision":"approved","note":"your_note","resolution":"grant","remove_member_rules":[]}'
```

### JavaScript

```javascript
const body = {
  "decision": "approved",
  "note": "your_note",
  "resolution": "grant",
  "remove_member_rules": []
};

const response = await fetch('https://api.elaichi.ai/access-request/<id>/resolve', {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer ' + process.env.ELAICHI_API_TOKEN,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify(body),
});

const data = await response.json();
console.log(data);
```

### Python

```python
import os
import requests

url = "https://api.elaichi.ai/access-request/<id>/resolve"
headers = {
    "Authorization": f"Bearer {os.environ['ELAICHI_API_TOKEN']}",
    "Content-Type": "application/json",
}
payload = {
    "decision": "approved",
    "note": "your_note",
    "resolution": "grant",
    "remove_member_rules": []
}

response = requests.post(url, headers=headers, json=payload)
print(response.json())
```
